CVE Tools

CVE-2026-73570

Exploited in the wild. In CISA KEV since 2026‑08‑21. A vendor fix is available.

Published Updated Sources: CVE.org, NVD

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check whether your Zimbra server is running Collaboration (ZCS) older than 10.1.20, and whether the optional zimbra-snmp package is installed.
  2. Verify whether SNMP notifications are enabled in your Zimbra/SNMP configuration.
  3. If both are true, plan to upgrade Collaboration to fixed version 10.1.20 (or later) using Zimbra’s official security guidance.
  4. If you cannot upgrade immediately, disable SNMP notifications and/or remove the zimbra-snmp package per vendor instructions, then confirm the change took effect.
  5. Document the date/time of the change and monitor for suspicious activity on the Zimbra host until the update is completed.

What it is

From the CVE record

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

In plain language

Written by AI from the record

If you run Zimbra Collaboration and have the optional zimbra-snmp package installed with SNMP notifications turned on, you should treat CVE-2026-73570 as an urgent remote takeover risk and update to 10.1.20 or later immediately.

CVE-2026-73570 is a remote code execution flaw in Zimbra Collaboration via SNMP notification processing: improper sanitization of untrusted input can let an unauthenticated attacker trigger arbitrary OS command execution as the Zimbra user when zimbra-snmp is installed and SNMP notifications are enabled; it is listed in CISA KEV with an action deadline of 2026-08-24.

If you're affected

  • Full server takeover
  • Malware installation risk
  • Customer email data compromise
  • Service outage and disruption

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS96th
CISA KEV
CISA KEV

Listed as exploited in the wild since 2026-08-21.

US federal agencies must remediate by 2026-08-24.

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

12% chance of exploitation activity in the next 30 days, which ranks it in the 96th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

18 events over 35 days, from the signal feeds we watch.

  1. EPSS band change0 → moderateepss band change
  2. Nuclei check added
  3. Analysis publishedZimbra's Optional SNMP Package Turned Into an Unauthenticated RCE — and CERT Polska Caught It Exploitedpatch available, record updated
  4. Patch availablerecord updated
  5. Added to CISA KEVpatch available, record updated, record updated
  6. Record updated

Affected products

Technical detail

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

Scored 8.9 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity HighRequires specific conditions like a race condition or non-default configuration
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope ChangedThe exploit can affect other components (e.g. sandbox escape, host compromise from VM)

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability LowReduced performance or intermittent disruption of service

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Collaboration, not every advisory. This one: actively exploited.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store